AWS Security Advisories · February 2013 — AWS Security Advisories
8 advisories 14 CVEs 2 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2013-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2013-151

ALAS · AL1ExploitedVulnCheck KEV listedImportant2013-02-03

ALAS-2013-151: java-1.7.0-openjdk (important)

CVEs:CVE-2012-3174

Affected products

ProductStatusVendorPackageEcosystem
java-1.7.0-openjdk affected Amazon java-1.7.0-openjdk
Upstream advisory

ALAS-2013-150

ALAS · AL1EPSS <= 49%Important2013-02-03

ALAS-2013-150: freetype (important)

CVEs:CVE-2012-5669

Affected products

ProductStatusVendorPackageEcosystem
freetype affected Amazon freetype
Upstream advisory

ALAS-2013-153

ALAS · AL1EPSS <= 49%Medium2013-02-04

ALAS-2013-153: php-ZendFramework (medium)

CVEs:CVE-2012-5657

Affected products

ProductStatusVendorPackageEcosystem
php-ZendFramework affected Amazon php-ZendFramework
Upstream advisory

ALAS-2013-154

ALAS · AL1EPSS <= 49%Medium2013-02-04

ALAS-2013-154: kernel, nvidia (medium)

CVEs:CVE-2013-0190

Affected products

ProductStatusVendorPackageEcosystem
kernel, nvidia affected Amazon kernel, nvidia
Upstream advisory

ALAS-2013-149

ALAS · AL1All remainingImportant2013-02-03

ALAS-2013-149: nss (important)

Affected products

ProductStatusVendorPackageEcosystem
nss affected Amazon nss
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.